We plan to bring eChai across 100 cities in India. It starts with eChai Startup Demo Day on 26 September, all in person. 11 cities confirmed, 129 founders registered. Any city that reaches 20 interested founders is on too. See your city
Building & Product

What can go wrong when an agent acts on my behalf, and how do I keep it safe?

The core risk is Simon Willison's lethal trifecta: an agent that can read your private data, sees untrusted content (any email or web page), and can communicate externally can be tricked by a poisoned message into leaking or destroying things, with no bug in your code required. Prompt injection remains unsolved, so design around it: give agents the minimum access needed, never combine all three capabilities in one agent, require human approval for anything that sends, spends or deletes, and log everything.

Go deeper

16 resources.

More in AI Agents

Also in Starting Up

The same ground, over in Build the product, our Starting Up track.

eChai Partner Brands